Privacy Policy

Last updated: June 2025

This Privacy Policy explains how Bluehappenworks Casino Hotel collects, uses, discloses, and protects your personal data when you visit our website at www.bluehappenworks.com, make a reservation, use our services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR), the Australian Privacy Act 1988, and all other applicable data protection legislation.

Please read this Privacy Policy carefully. By accessing or using our website and services, you acknowledge that you have read and understood this policy. If you do not agree with the practices described herein, please discontinue use of our website and services.

1. Data Controller

The entity responsible for processing your personal data (the "Data Controller") is:

Legal Entity Name Bluehappenworks Casino Hotel
Trading Name Bluehappenworks Casino Hotel
Registration Country Australia
Registration Number HRB 123456 B
VAT Number AU 123456789
Registered Address 81 Talavera Rd, North Ryde NSW 2113, Australia
Website www.bluehappenworks.com
Privacy Contact Email privacy@bluehappenworks.com

1.1 Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection legislation. You may contact our DPO directly regarding any questions or concerns about how we handle your personal data:

Title The Data Protection Officer
Organisation Bluehappenworks Casino Hotel
Address 81 Talavera Rd, North Ryde NSW 2113, Australia
Email privacy@bluehappenworks.com

2. Personal Data We Collect

We collect personal data that you provide to us directly, data that is generated automatically when you use our website or services, and data that we receive from third parties. The categories of personal data we may collect include, but are not limited to, the following:

2.1 Identity and Contact Data

  • Full name (first name, last name)
  • Date of birth and age verification information
  • Gender
  • Nationality and country of residence
  • Government-issued identification document details (e.g., passport number, driver's licence number) where required by law
  • Postal address (home and billing address)
  • Email address
  • Telephone number(s)
  • Profile photograph (where voluntarily provided)

2.2 Reservation and Stay Data

  • Booking reference numbers and confirmation details
  • Check-in and check-out dates
  • Room type and preferences
  • Number of guests and guest details
  • Special requests and accessibility requirements
  • Loyalty programme membership details
  • History of previous stays and interactions with our establishment

2.3 Financial and Payment Data

  • Credit card or debit card details (processed securely via PCI-DSS compliant payment processors; we do not store full card numbers)
  • Bank account information (where applicable for refunds or transfers)
  • Transaction history and records
  • Invoicing and billing records

2.4 Casino and Gaming Data

  • Casino membership and player club information
  • Gaming activity records (types of games played, session duration, amounts wagered and won)
  • Self-exclusion programme participation and responsible gambling records
  • Age and identity verification records as required by the Casino Control Act 1992 (NSW) (Australia) and any other applicable gaming regulations
  • Anti-money laundering (AML) and Know Your Customer (KYC) verification information

2.5 Website and Technical Data

  • IP address
  • Browser type and version
  • Operating system and device type
  • Pages visited and time spent on each page
  • Referring website URL
  • Date and time of access
  • Cookie identifiers and session data (see our Cookie Policy for further details)
  • Clickstream data and interaction data

2.6 Marketing and Communication Data

  • Marketing preferences and opt-in/opt-out records
  • Communication history (including emails, letters, and records of telephone calls where calls are recorded)
  • Survey responses and feedback submissions
  • Competition and promotional entry details

2.7 Special Categories of Personal Data

In limited circumstances, we may collect special categories of personal data as defined under Article 9 of the GDPR. These include:

  • Health data: Accessibility and dietary requirements, allergy information, or medical conditions that you voluntarily disclose to enable us to accommodate your needs during your stay.
  • Biometric data: Where required for access control or security purposes and where permitted by law.

We will only process special categories of personal data where we have your explicit consent, where processing is necessary to protect your vital interests, or where we are otherwise permitted to do so under applicable law. You are never obligated to provide special category data to us; however, failure to do so may limit our ability to fulfil specific service requests.

2.8 Data Collected from Third Parties

We may also receive personal data about you from the following third-party sources:

  • Online travel agencies and booking platforms (e.g., Booking.com, Expedia)
  • Corporate travel management companies making bookings on your behalf
  • Credit reference and fraud prevention agencies
  • AML and KYC screening service providers
  • Social media platforms (where you engage with our social media presence or use social login features)
  • Analytics and advertising partners

4. How We Use Your Personal Data

We use the personal data we collect for the following specific purposes:

4.1 Hotel and Accommodation Services

  • Processing, managing, and confirming your reservations and bookings
  • Facilitating your check-in and check-out processes
  • Providing in-stay services including room service, concierge, housekeeping, and dining
  • Accommodating special requests, dietary needs, and accessibility requirements
  • Managing your loyalty programme membership and associated benefits
  • Processing payments and issuing invoices and receipts
  • Managing cancellations, amendments, and refunds

4.2 Casino and Gaming Operations

  • Verifying your identity and age as required by gambling regulations
  • Registering and managing your casino membership
  • Recording and reporting gaming transactions as required by law
  • Conducting AML and KYC checks
  • Administering responsible gambling measures, including self-exclusion programmes
  • Detecting and preventing fraudulent or suspicious gaming activity
  • Providing player rewards and loyalty benefits

4.3 Customer Communications and Support

  • Responding to your enquiries, complaints, and requests
  • Sending booking confirmations, pre-arrival information, and post-stay follow-up communications
  • Providing customer support and resolving disputes
  • Notifying you of changes to our services, policies, or terms and conditions

4.4 Marketing and Personalisation

  • Sending you promotional offers, newsletters, and information about our hotel, casino, dining, and events (subject to your marketing preferences)
  • Personalising communications and offers based on your stay history, preferences, and interests
  • Conducting competitions, prize draws, and promotional activities
  • Displaying targeted advertising on our website and third-party platforms (subject to your cookie and advertising preferences)

4.5 Security and Safety

  • Operating CCTV systems throughout our premises to ensure the safety and security of guests, staff, and property
  • Managing physical access to restricted areas of our property
  • Preventing and investigating theft, fraud, and other criminal activity
  • Ensuring compliance with health and safety regulations
  • Responding to emergencies on our premises

4.6 Legal and Regulatory Compliance

  • Fulfilling our obligations under applicable laws and regulations
  • Responding to requests from regulatory bodies, law enforcement agencies, and courts
  • Establishing, exercising, or defending legal claims
  • Maintaining records required by tax and accounting laws

4.7 Business Analytics and Improvement

  • Analysing website traffic, usage patterns, and user behaviour to improve our website and online services
  • Conducting market research and guest satisfaction surveys
  • Generating internal business reports and performance analytics
  • Developing new products, services, and offerings

5. Sharing Your Personal Data

We do not sell your personal data to third parties. However, we may share your personal data with the following categories of recipients where necessary and in accordance with applicable law:

5.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf and under our instruction. These include:

  • IT and technology providers: Hosting services, cloud computing providers, property management system providers, and software vendors
  • Payment processors: Secure payment gateway providers and card processing companies (PCI-DSS compliant)
  • Booking and reservation platforms: Online travel agencies and channel management systems
  • Marketing and communications: Email marketing platforms, CRM system providers, and advertising technology partners
  • Customer support: Call centre and customer support technology providers
  • Analytics providers: Website analytics and business intelligence platforms
  • Security providers: CCTV monitoring services and physical security companies
  • AML and KYC verification providers: Identity verification and screening services

All third-party processors are required to implement appropriate technical and organisational security measures and are only permitted to process your personal data in accordance with our instructions and applicable data protection law.

5.2 Regulatory and Law Enforcement Authorities

We may disclose your personal data to the following authorities where required or permitted by law:

  • The Australian Federal Police
  • Liquor & Gaming NSW
  • AUSTRAC and other financial crime regulators
  • The Australian Taxation Office (ATO)
  • Other regulatory bodies, tax authorities, and government agencies as required
  • Courts and judicial bodies in connection with legal proceedings

5.3 Business Partners

Where you have provided your consent or where we have another lawful basis to do so, we may share your personal data with selected business partners for the following purposes:

  • Joint marketing and promotional activities
  • Linked loyalty programme partners
  • Event management and entertainment partners providing services on our premises

5.4 Corporate Transactions

In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency, your personal data may be transferred to the relevant third party as part of that transaction. We will notify you of any such change in data controller and ensure appropriate protections are in place.

5.5 International Data Transfers

As a business operating within Australia, the majority of your personal data is stored and processed within Australia or the European Economic Area (EEA). However, some of our service providers may operate in or transfer data to countries outside of Australia and the EEA. Where personal data is transferred to a country that does not provide an equivalent level of data protection, we will ensure that appropriate safeguards are in place, which may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions recognised by the relevant data protection authority
  • Binding Corporate Rules (BCRs) where applicable
  • Other legally approved transfer mechanisms

You may request further information about international data transfers and the safeguards in place by contacting us at privacy@bluehappenworks.com.

6. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. The criteria we use to determine appropriate retention periods include the nature and sensitivity of the data, the purposes for which it is processed, applicable statutory limitation periods, and regulatory requirements.

The following retention periods apply as a general guideline:

Category of Data Retention Period Reason
Guest reservation and stay records 7 years from the date of stay Legal and tax obligations; limitation periods for civil claims
Financial and payment records 7 years from the date of transaction Tax and accounting obligations under Australia law
Casino membership and gaming records 7 years from the date of last activity or account closure Gambling regulatory requirements and AML obligations
AML/KYC verification records 5 years from the end of the business relationship Anti-Money Laundering and Countering Financing of Terrorism Act 2009
CCTV footage 31 days (unless required for investigation or legal proceedings) Security purposes; proportionality principle
Marketing and communication preferences Until you withdraw consent or opt out, plus 1 year Compliance with marketing opt-out records
Website analytics and technical data Up to 26 months Business analytics and improvement
Customer complaints and correspondence 3 years from resolution Legal claims and dispute resolution
Responsible gambling and self-exclusion records Duration of exclusion plus 5 years Regulatory compliance and duty of care obligations

Upon expiry of the applicable retention period, your personal data will be securely deleted, anonymised, or destroyed in accordance with our data retention and disposal procedures. Where data is anonymised, it may be retained indefinitely for statistical and analytical purposes.

7. Your Rights Under Data Protection Law

Subject to applicable data protection legislation, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to certain exceptions and limitations under applicable law.

7.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you and to receive information about how we process it. This is commonly referred to as a Subject Access Request (SAR). We will respond to your request within one month of receipt, which may be extended by a further two months in complex or numerous cases.

7.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.

7.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you have withdrawn your consent and no other legal basis applies, or where the data has been unlawfully processed. This right does not apply where we are required to retain the data to comply with a legal obligation or to establish, exercise, or defend legal claims.

7.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example, where you contest the accuracy of the data, where processing is unlawful and you oppose erasure, or where you have objected to processing and we are verifying whether our legitimate interests override your rights.

7.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on the performance of a contract, and processing is carried out by automated means, you have the right to receive a copy of your personal data in a structured, commonly used, and machine-readable format, and to request that we transmit that data directly to another controller where technically feasible.

7.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data:

  • Legitimate interests: Where we process your data on the basis of our legitimate interests, you may object on grounds relating to your particular situation. We will cease processing unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
  • Direct marketing: You have an unconditional right to object to processing of your personal data for direct marketing purposes at any time. Upon receipt of such an objection, we will cease processing your data for that purpose immediately.

7.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we engage in automated decision-making that has significant effects, we will inform you accordingly and provide you with the opportunity to request human review, to express your point of view, and to contest the decision.

7.8 Right to Withdraw Consent (Article 7(3) GDPR)

Where we process your personal data on the basis of your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

7.9 How to Exercise Your Rights

To exercise any of your rights, please submit a written request to us using the contact details provided in Section 8 below. We may need to verify your identity before processing your request. We will respond to your request within one calendar month. There is no charge for exercising your rights, unless requests are manifestly unfounded or excessive, in which case we reserve the right to charge a reasonable fee or refuse to act on the request.

7.10 Right to Lodge a Complaint

If you are not satisfied with how we handle your personal data or with our response to a rights request, you have the right to lodge a complaint with the relevant supervisory authority. In Australia, the relevant authority is:

Authority Office of the Australian Information Commissioner (OAIC)
Website www.oaic.gov.au
Phone 1300 363 992
Address GPO Box 5218, Sydney NSW 2001, Australia

If you are located within the European Economic Area (EEA), you also have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first so that we may address your concerns directly before escalating to a supervisory authority.

8. Cookies and Similar Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic, and deliver relevant content and advertising. Cookies are small text files that are stored on your device when you visit our website.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the operation of our website, including session management and security functions. These cookies cannot be disabled.
  • Performance and Analytics Cookies: Used to collect information about how visitors use our website, helping us improve functionality and user experience (e.g., Google Analytics).
  • Functional Cookies: Used to remember your preferences and personalise your experience on our website.
  • Targeting and Advertising Cookies: Used to deliver relevant advertisements and track the effectiveness of our marketing campaigns on third-party platforms.

Upon your first visit to our website, you will be presented with a Cookie Consent Banner through which you can accept or decline non-essential cookies. You may update your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of our website.

For full details of the cookies we use, their purposes, and how to manage them, please refer to our full Cookie Policy.

9. Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, disclosure, alteration, loss, or destruction. These measures include, but are not limited to:

  • Encryption of data in transit using TLS (Transport Layer Security) and encryption of sensitive data at rest
  • Secure and access-controlled data storage systems
  • Role-based access controls limiting access to personal data to authorised personnel only
  • Regular security assessments, penetration testing, and vulnerability management
  • Staff training on data protection and information security
  • PCI-DSS compliant payment processing for all card transactions
  • Incident response and data breach notification procedures

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and we will notify you without undue delay where required by law.

Please note that no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee its absolute security. We encourage you to use strong passwords, keep your account credentials confidential, and notify us immediately if you suspect any unauthorised access to your account.

10. Children's Privacy

Our casino services are strictly available to persons aged 18 years and over in compliance with Australian gambling legislation. Our website is not directed at children under the age of 18, and we do not knowingly collect personal data from children under this age in relation to our casino services.

Hotel accommodation services may be used by families with children; however, personal data relating to minors will only be processed to the extent necessary to fulfil the hotel booking and will be handled with the utmost care. Where parental or guardian consent is required for the processing of a minor's data, we will seek such consent.

If you believe that we have inadvertently collected personal data from a child without appropriate consent, please contact us immediately at privacy@bluehappenworks.com so that we may take appropriate steps to delete such data.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or regulatory requirements. The date at the top of this policy indicates when it was last revised. Material changes will be communicated to you by posting a prominent notice on our website or, where appropriate, by direct notification to you by email.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website and services following any update constitutes your acknowledgement of the revised policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we process your personal data, please do not hesitate to contact us using the following details:

Data Controller Bluehappenworks Casino Hotel
Contact Person The Data Protection Officer
Postal Address 81 Talavera Rd, North Ryde NSW 2113, Australia
Email Address privacy@bluehappenworks.com
Website www.bluehappenworks.com

We are committed to addressing your queries and concerns promptly and in a transparent manner. If you are not satisfied with our response, you retain the right to lodge a complaint with the Office of the Australian Information Commissioner or any other competent supervisory authority, as described in Section 7.10 of this policy.